Количество 353 972
Количество 353 972
GHSA-2p4v-77rh-r7fj
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.
GHSA-2p4r-xjwx-3whg
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.
GHSA-2p4r-h63c-pgmr
The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-2p4q-qchf-h9q6
A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific configurations.
GHSA-2p4q-qc9j-27gx
Windows Hyper-V Denial of Service Vulnerability
GHSA-2p4q-q7j4-q23g
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check BIOS images before it is used BIOS images may fail to load and null checks are added before they are used. This fixes 6 NULL_RETURNS issues reported by Coverity.
GHSA-2p4q-pg24-pmp6
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949.
GHSA-2p4q-mvv4-rjr2
Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.
GHSA-2p4m-4mc7-m8w7
A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter Driver. Executing a manipulation can lead to improper access controls. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-2p4j-rf5v-mxpv
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.
GHSA-2p4j-8pc7-8jg8
The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php.
GHSA-2p4j-7hmq-hf5r
A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks.
GHSA-2p4j-3h9f-v3pj
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-2p4h-vppg-wjv6
BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extract database schema information and table contents from the application database.
GHSA-2p4h-6x4f-47jj
Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions.
GHSA-2p4g-jrmx-r34m
Rancher Login Parameter Can Be Edited
GHSA-2p4f-vc9q-r5vp
Typo3 Arbitrary file upload and XML External Entity processing
GHSA-2p4f-q7g6-g44m
A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.
GHSA-2p4f-5m6f-7653
GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.
GHSA-2p49-hgcm-8545
SVGO removeScripts plugin leaves some executable scripts intact
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2p4v-77rh-r7fj All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-2p4r-xjwx-3whg Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
GHSA-2p4r-h63c-pgmr The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | около 2 лет назад | |
GHSA-2p4q-qchf-h9q6 A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability only impacts specific configurations. | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
GHSA-2p4q-qc9j-27gx Windows Hyper-V Denial of Service Vulnerability | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
GHSA-2p4q-q7j4-q23g In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check BIOS images before it is used BIOS images may fail to load and null checks are added before they are used. This fixes 6 NULL_RETURNS issues reported by Coverity. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-2p4q-pg24-pmp6 IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; and Tivoli Storage FlashCopy Manager 3.1 before 3.1.1.5, 3.2 before 3.2.1.7, and 4.1 before 4.1.2, when application tracing is used, place cleartext passwords in exception messages, which allows physically proximate attackers to obtain sensitive information by reading trace output, a different vulnerability than CVE-2015-4949. | 0% Низкий | около 4 лет назад | ||
GHSA-2p4q-mvv4-rjr2 Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-2p4m-4mc7-m8w7 A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter Driver. Executing a manipulation can lead to improper access controls. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-2p4j-rf5v-mxpv Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
GHSA-2p4j-8pc7-8jg8 The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to obtain valid e-mail addresses to conduct spam attacks by modifying the contact_id parameter to index2.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-2p4j-7hmq-hf5r A stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of Proxmox Virtual Environment (PVE) 8.4. Authenticated users can inject JavaScript code that is later executed in the browsers of users who view the configuration page, enabling client-side attacks. | CVSS3: 5.4 | 0% Низкий | 11 месяцев назад | |
GHSA-2p4j-3h9f-v3pj Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1% Низкий | около 4 лет назад | ||
GHSA-2p4h-vppg-wjv6 BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extract database schema information and table contents from the application database. | CVSS3: 8.2 | 0% Низкий | 5 месяцев назад | |
GHSA-2p4h-6x4f-47jj Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <= 2.1 versions. | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-2p4g-jrmx-r34m Rancher Login Parameter Can Be Edited | CVSS3: 4.7 | 2% Низкий | около 4 лет назад | |
GHSA-2p4f-vc9q-r5vp Typo3 Arbitrary file upload and XML External Entity processing | около 2 лет назад | |||
GHSA-2p4f-q7g6-g44m A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php. | 1% Низкий | около 4 лет назад | ||
GHSA-2p4f-5m6f-7653 GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands. | 0% Низкий | больше 4 лет назад | ||
GHSA-2p49-hgcm-8545 SVGO removeScripts plugin leaves some executable scripts intact | CVSS3: 8.2 | 13 дней назад |
Уязвимостей на страницу